In the rapidly evolving world of cloud computing, Cisco's acquisition of Valtix represents a significant stride in the tech giant's multicloud security strategy. Vishal Jain, VP for Cisco Multicloud Defense and co-founder of Valtix, explained how Cisco addresses the challenges organizations face when trying to secure beyond cloud applications.
When Jain co-founded Valtix, the startup aimed to take a multicloud approach to solving cloud security challenges. It centralizes and consolidates network security across major cloud platforms and offers a cloud security platform that delivers capabilities including cloud-based firewall, web application firewall (WAF), intrusion detection systems (IDS) and intrusion prevention systems (IPS), egress filtering, and data loss prevention (DLP) for Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), and Oracle Cloud Infrastructure (OCI).
Initially focusing on visibility, Valtix soon realized the growing need for real-time prevention against threats.
“The main thing we noticed was that cloud is a lot more dynamic,” Jain told SDxCentral. “It's not just the applications are dynamic, they're scaling up, they're failing over, but also the infrastructure underneath and also the perimeter around it, which is dynamic.”
“So in that world, we saw that the challenges were if you take anything built for on prem and take it to the cloud, you actually don't get the right zero trust, you actually become less secure. And also those solutions were a lot more complex,” he added.
Cisco Multicloud Defense for multicloud securityIn February, Cisco announced the acquisition of Valtix and the integration of its technology into Cisco’s existing security services. Later in June, the vendor launched Cisco Multicloud Defense, based on the acquisition.
Cisco's Multicloud Defense is designed to extend the traditional firewall concept into the multicloud and enables SecOps teams to manage security across multiclouds with a single policy, in real time, from a single software-as-a-service (SaaS) platform.
Jain explained the service includes two key components: the SaaS control plane and the platform-as-a-service delivery.
The SaaS control plane offers visibility, automation, security policy management and cloud security orchestration, while the platform as a service delivers distributed firewall capabilities across various cloud environments. This approach addresses inbound, lateral and egress threats and incorporates advanced security features like decryption, intrusion detection systems (IDS), intrusion prevention systems (IPS) and malware protection, supported by Cisco Talos intelligence, according to Jain.
“We define and allow the policies to be done to the cloud tags because the cloud controller consumes all those cloud tags from the cloud. It can do all the translation,” he added.
Why Teradata picked Multicloud DefenseDuring the AWS re:Invent 2023, Cisco showcased the Multicloud Defense use case for its customer Teradata. Jain highlighted how Cisco's solutions have streamlined provisioning, upgrades and policy changes, transforming hours of manual work into minutes and reducing infrastructure costs by 35%.
“They are truly multicloud because their customers are multicloud,” he said. “So they are in AWS, Azure, GCP [Google Cloud Platform], and they run hundreds of workloads across each cloud, and again they wanted a single policy and automation around along this dynamic infrastructure.”
To address these challenges, Jain said Cisco Multicloud Defense provides the following:
- Rapid security provisioning for Teradata's need to get customers onboard quickly without impacting service delivery.
- Streamlined security rule updates at scale, as Teradata operates thousands of cloud sites.
- Reduced infrastructure costs through the use of single gateways in each virtual private cloud (VPC) and improved failover capabilities.
- Seamless upgrades with zero downtime enabled by the cloud-native architecture, including the use of a gateway load balancer.
Cisco aims to bridge the security policy management across public multiclouds and on-premises environments using Cisco Defense Orchestrator.
“Cisco is the only one with this combined solution doing zero trust between the on prem and the cloud,” Jain said. “The key thing we do is that policy is driving everything across workloads, VPCs, accounts, clouds with the integration.”
He said policy can define connectivity, security services, scaling and availability across the hybrid cloud environments.
Comments